# Serve agents to the public with PublicSurface

> AgentOS's new PublicSurface serves selected agents, teams, workflows and a stateless MCP server to anonymous users, with shared rate limits, request and output bounds, CORS and service authentication.

- Published: 2026-09-08
- Author: Ashpreet Bedi
- Categories: Changelog
- Canonical: https://www.agno.com/articles/serve-agents-to-the-public-with-publicsurface
- Markdown: https://www.agno.com/articles/serve-agents-to-the-public-with-publicsurface.md

Pass `public=PublicSurface(...)` to Agno's `AgentOS` and list the components anonymous users may reach. AgentOS keeps everything you leave off that list private, and every public request runs against quotas and bounds.

<Video
  src="/videos/changelog-public-surface-terminal.mp4"
  controls
  preload="metadata"
  aria-label="A terminal recording of an anonymous caller on an AgentOS PublicSurface: /agents lists only the public agent, and /config returns a sanitized not_found error"
/>

Say you want a product assistant on your marketing site. Visitors aren't logged in, and you don't want them anywhere near your admin API, your internal teams or the workflow that re-syncs your docs. `PublicSurface` draws that line in the `AgentOS` constructor.

```python
agent_os = AgentOS(
    id="product-assistant",
    db=db,
    agents=[assistant],
    public=PublicSurface(
        agents=[assistant],
        limits={
            "run": RateLimit(
                client_per_minute=10,
                global_per_minute=50,
                client_per_day=80,
                global_per_day=3000,
            )
        },
    ),
    cors_allowed_origins=["https://your-product.example"],
)
```

![What PublicSurface exposes: anonymous clients reach only the selected agent, team and stateless MCP server, through shared quotas and request bounds. The sync workflow needs a service token, and team members and the admin API stay private.](https://www.agno.com/images/v3-0-7-public-surface.png)

### How are public requests limited?

`PublicSurface` enforces per-client and global limits, per minute and per day. AgentOS counts them in PostgreSQL, so every replica enforces the same numbers. Request bodies, run time, output size and concurrent runs all have ceilings you can set.

### What happens to teams and workflows?

A selected team is public over REST, with gzip. AgentOS reduces its roster, and its members' routes stay private unless you select them too.

A public workflow still needs service credentials, so knowing its URL doesn't let anyone trigger it.

### Can I serve tools over MCP?

`PublicSurface` can serve explicit tools to anonymous clients over a native, stateless MCP server.

Learn more about [Public Surface](https://docs.agno.com/agent-os/public-surface) in the documentation. For a production example, see [how we built the Agno Docs Agent](https://docs.agno.com/use-cases/documentation-agents/how-we-built-it).
